Security
How Cockpit keeps each business's data safe and separate. Everything on this page is how the service works today; anything still to come says so.
Each business kept apart
- Every business's posts, messages, stores, reports and logins are stored separately, and every request is checked against the signed-in person's access to that business.
- An automated audit signs in as each business every two hours and checks every page on desktop and phone for anything belonging to another business.
- Each business publishes through its own space with its own keys.
Encryption
- In transit: every page and every connection is HTTPS (TLS 1.2 or later), with HTTP Strict Transport Security for a year. Calls from Cockpit to social platforms, stores and points of sale are HTTPS too.
- At rest: the server's disks and backups are encrypted by the hosting provider (AES-256). On top of that, the logins a business gives Cockpit to read its store or point of sale are sealed by Cockpit with AES-256-GCM, each bound to its own business, with a key only the service can read.
- Backups: taken every night, sealed with RSA-OAEP and AES-256 so that only VEROXA's offline key opens them, and kept 14 days. A full restore was rehearsed on 29 September 2026.
Signing in
- Passwords are stored as scrypt hashes, never in readable form. Repeated failed sign-ins lock the account for a while.
- Two-step sign-in with any authenticator app is available on every account (Account → Two-step sign-in), with single-use recovery codes. VEROXA staff use it.
- Sign in with Google is available; when two-step is on, Cockpit still asks for its code after Google.
- Roles per business: owner, manager, viewer and approver (an approver can approve or send back waiting posts and nothing else). Changes are recorded in an audit log.
Connected accounts
- Cockpit asks each platform only for what it uses. Store and point-of-sale connections are read only; Cockpit writes nothing to them.
- Disconnecting a store, point of sale or inbox (Settings → Connections) deletes Cockpit's copy of that login and of everything read through it, at once.
- Ad spend needs an owner or manager, a budget they type, and limits they set; any boost can be stopped from Cockpit.
Payments and AI
- Card payments are handled by our payment processor on its own pages; Cockpit never sees or stores card numbers.
- Your content is sent to AI services only to do what you asked (write, picture, voice, answer), and under our terms with them it is not used to train their models. The companies involved are listed on the sub-processors page.
The server
- Only the web ports (443, and 80 to redirect to it) are open to the internet. Operating system security updates install automatically.
- Browser protections on every page: never shown inside another site (one exception: Cockpit's page inside a store's own Shopify admin, which only that admin may show), no type guessing, no full addresses sent to other sites, no camera, microphone or location access.
- Keys for outside services are kept on the server in a write-only store: no screen can read them back, and they are never in source code or logs.
Watching and responding
- A health check every 10 minutes, a separate server outside Cockpit's main one checking the app, sign-in and publishing every minute, and a full audit every two hours, with alerts to VEROXA. Service status.
- A written incident plan: contain first (revoke affected logins, rotate keys), then tell affected businesses without undue delay, platforms within their stated windows and authorities where the law requires, and write up what changes. The plan is reviewed every six months.
Certifications
Cockpit is not certified to SOC 2 or ISO 27001 yet. When it is, it will say so here. Security questionnaires from customers are welcome at hello@veroxa.co.
Report a problem
If you think you have found a security problem, write to hello@veroxa.co with "Security" in the subject. We answer within two business days, keep you told while we fix it, and do not take action against good-faith research that avoids other people's data and does not disrupt the service. Machine-readable contact: security.txt.
Contact
VEROXA LLC · 1480 Crabb River Rd, Richmond, TX 77469, USA · hello@veroxa.co · Privacy policy · Sub-processors